From nobody Mon Sep 21 07:31:41 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hpFKT4LJXz6tPdl for ; Mon, 21 Sep 2026 07:31:41 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hpFKT3tNXz4fjC for ; Mon, 21 Sep 2026 07:31:41 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789975901; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=vr2gIupXwKFUDeh0r50CLNwM25ooA5l2GAnl/D+FXzE=; b=GkjouYhcTtDnFCZ9YKa9v2MnalpVKx0l1k6u+v7YGOJeIfiKyHznDz+tK8e0lPnQBnw9Cw QkhaYfjVvU1muDMpds+0TO3cD+VP6VemXg2ULKzbtFmMK5J/LQFZv1IqJjXiSsqORUQ+X8 bWThWNsPIvUAFg8pjVQOxg1tzc/j7MdllXUI/u7GtkHOfUVRdZByXJ+Dqp4ekXckpHaHhM diAMID/htgibbr6oTdT4q78/BKgzOWBQZUHVAgVwZ4vgK6MGM/KKkpsWNs+zwwD2RPWStM d5iercxcq1joJbRWjeA97TX7eCBje8wKfZUa39evtb+OyIpLLfnmE6YRprh+qA== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1789975901; b=a4bLo8BN0ceLwq3a/f6BmJfQ1cPLvn1lZpaOXGvjPXeT+ihVMg6APjv4Q3yLl8sRUSxAGI WBW7ws2xc1pH7L+yiBiGFDVNFlTo0ZF7l8VdCHInZQVCeaZwnklfWU8KNP2vXQKxwq5Nkm /s456k3lRQr4B4tjRVU6Vx9HzMpI/4g7jxO+NmiyNx+si43QnghDsElDYJ5WStLkiftTaE /+7pHa5/1rSI8PE733CMlTa6UQCeYPgn2G+P8dwLSRpzxrhIVxfYqIfAELdl2nmgmfwSZd dy1T8KJ6ZRcYGtj1ieWO86+TQW3y022TrdIo7kZ9JRZhm/jbZ1hLvMSGwccZlg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1789975901; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=vr2gIupXwKFUDeh0r50CLNwM25ooA5l2GAnl/D+FXzE=; b=RRBGSeXGdF8mDrK4xX/KqJBHfdObDjgBGu9pSxwXV/RY2yzU7n9nFc/87xVzuXYERVhddf QAqnjduSJzS2RHgko+2pOfiSuBiIoViaIM6tcm9f5Erixn3sBJCpubiMq0u37rzBxbMar5 omjBJsg1RaxBd52lW5Za9ppxvdH2d2iJAjK7ZUWWeIGhNHEombcmoe1pp4P2MP7phA+AT6 YcX/t8+plNYCkETegMKSZ9TGzDhzsRpNxMnEwZOFzXaBQywnnaueoY3utSL5nOHpxciKdP cFqcoOppJoCK622hXovYQ8hNa80syzw+aMWPcnQ5MZzGVRp+YU0rhddoGw7Shw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hpFKT2z0fz19NL for ; Mon, 21 Sep 2026 07:31:41 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 459bf by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 21 Sep 2026 07:31:41 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Piotr Kubaj Subject: git: 191bfb69602d - stable/15 - powerpc/radix: take the pmap lock in mmu_radix_sync_icache() List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: pkubaj X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 191bfb69602d49cd080db0e1ca914e48ddf54eab Auto-Submitted: auto-generated Date: Mon, 21 Sep 2026 07:31:41 +0000 Message-Id: <6ab0dd5d.459bf.5898fc8a@gitrepo.freebsd.org> The branch stable/15 has been updated by pkubaj: URL: https://cgit.FreeBSD.org/src/commit/?id=191bfb69602d49cd080db0e1ca914e48ddf54eab commit 191bfb69602d49cd080db0e1ca914e48ddf54eab Author: Piotr Kubaj AuthorDate: 2026-09-01 06:52:06 +0000 Commit: Piotr Kubaj CommitDate: 2026-09-21 07:31:35 +0000 powerpc/radix: take the pmap lock in mmu_radix_sync_icache() mmu_radix_sync_icache() walked the page tables with an unlocked pmap_extract() and passed the result straight to PHYS_TO_DMAP(), checking only that it was non-zero. Nothing keeps the mapping - or the page table page holding it - alive across that window: if another thread of the same process tears a mapping down concurrently, the page table page can be freed and reused, so pmap_extract() reads arbitrary memory and returns a bogus physical address. __syncicache() then dereferences an unmapped direct map address and the kernel takes a data storage interrupt: fatal kernel trap: exception = 0x300 (data storage interrupt) virtual address = 0xc003317ca6022a00 dsisr = 0x40000000 srr0 = 0xc000000000f59460 (__syncicache) lr = 0xc000000000f23588 (mmu_radix_sync_icache) pid = 23878, comm = skyframe-evaluator- panic: data storage interrupt trap The faulting addresses decode to physical addresses far beyond installed memory (~140 TB and ~900 TB on a 256 GB machine), i.e. translations that never existed. The hash MMU implementation of the same method, moea64_sync_icache(), already holds PMAP_LOCK() across the loop; do the same here. mmu_radix_extract() does not acquire the pmap lock itself, so this introduces no recursion. JIT workloads reach this path constantly: ppc_instr_emulate() calls pmap_sync_icache() on the faulting address for the SIGILL "second chance" retry, so a multithreaded JVM executing freshly written code races against its own threads' mmap/munmap. Every panic observed here was in a JVM thread. Tested on POWER9 (radix MMU) with a bazel/JVM build loop that previously panicked the machine twice within ten minutes: afterwards 13 consecutive builds and more than 10 hours of uptime with no panic, on both 15.1-RELEASE and 16.0-CURRENT. MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D59311 Reviewed by: jhibbits, adrian (cherry picked from commit 1574ca1955f55151c4c76b978c8a772ac3abfa9f) --- sys/powerpc/aim/mmu_radix.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/sys/powerpc/aim/mmu_radix.c b/sys/powerpc/aim/mmu_radix.c index 387c172b446c..e54fdbb80933 100644 --- a/sys/powerpc/aim/mmu_radix.c +++ b/sys/powerpc/aim/mmu_radix.c @@ -5985,6 +5985,7 @@ mmu_radix_sync_icache(pmap_t pm, vm_offset_t va, vm_size_t sz) if (__predict_false(pm == NULL)) pm = &curthread->td_proc->p_vmspace->vm_pmap; + PMAP_LOCK(pm); while (sz > 0) { pa = pmap_extract(pm, va); sync_sz = PAGE_SIZE - (va & PAGE_MASK); @@ -5996,6 +5997,7 @@ mmu_radix_sync_icache(pmap_t pm, vm_offset_t va, vm_size_t sz) va += sync_sz; sz -= sync_sz; } + PMAP_UNLOCK(pm); } static __inline void